What matters in AI.

Subscribe

Learn / AI agents

Definition · AI agents

AI workflow

An AI workflow is a system in which LLMs and tools are orchestrated through predefined code paths. The developer fixes the sequence and its conditions, so the model is a step inside the pipeline rather than the thing directing it. Anthropic contrasts AI workflows with AI agents, where the model directs its own process.

Last reviewed

Key points

  • An AI workflow is the predefined-code-path end of the agentic spectrum: the developer fixes the sequence, and the model is a step inside it, not its director.
  • Anthropic draws the line: workflows are 'systems where LLMs and tools are orchestrated through predefined code paths', while agents are 'systems where LLMs dynamically direct their own processes and tool usage'.
  • OpenAI's practical guide says applications that integrate LLMs but do not use them to control workflow execution — simple chatbots, single-turn LLMs, sentiment classifiers — are not agents.
  • A workflow executes with the credentials its creator configured, decoupling the identity that triggers it from the identity that acts — the root cause of workflow identity hijacking.
  • Anthropic's five workflow patterns are prompt chaining, routing, parallelization, orchestrator-workers, and evaluator-optimizer.

An AI workflow fixes the path before it runs: the developer sets the steps, and the model handles the parts needing judgement.

What separates a workflow from an agent

The difference is whose code chooses the next step. In a workflow that choice is the developer’s; the model is one step inside a predetermined pipeline. Anthropic draws the line in “Building effective agents”: workflows are “systems where LLMs and tools are orchestrated through predefined code paths”, whereas agents are “systems where LLMs dynamically direct their own processes and tool usage”. The workflow is the deterministic end of the spectrum; the AI agent is the model-directed end.

OpenAI’s practical guide defines a workflow as “a sequence of steps that must be executed to meet the user’s goal”, drawing the line from the other side: applications that do not use their LLM “to control workflow execution” — “simple chatbots, single-turn LLMs, or sentiment classifiers” — are not agents. A workflow need not contain a model at all; it becomes an AI workflow when one sits in the steps.

Why it matters

A workflow runs with the identity its creator configured: a step that sends a reply, writes a row, or calls an API uses a service account or developer key the creator stored, not the permissions of whoever triggered it. Noma Labs states the consequence: “the identity and permissions of the user who triggers a workflow are decoupled from the identity and permissions used to execute it”. That decoupling is the root cause of workflow identity hijacking: an unauthenticated request runs with privileges the requester never had, and a prompt injection filter sees nothing wrong because nothing in the request is wrong.

The same property makes workflows quieter targets than agents: the failure is architectural and the fix is too — an authorization checkpoint before sensitive actions, short-lived scoped credentials, and no shared path between sensitive reads and automated replies.

In practice

Anthropic names five shapes that recur in production.

  • Prompt chaining decomposes a task into a sequence of steps, each LLM call processing the previous output, with optional programmatic gates between steps.
  • Routing classifies an input and sends it to the right specialist — a small cheap model for easy questions, a stronger one for hard ones.
  • Parallelization runs independent subtasks at once, or the same task several times and combines the outputs.
  • Orchestrator-workers lets a central LLM break a task into subtasks it delegates to worker calls, then synthesizes their results.
  • Evaluator-optimizer loops a generator against an evaluator until the output passes.

These are common patterns, not a taxonomy; Anthropic notes they can be shaped and combined to fit a use case.

Where definitions disagree

Whether a system is a workflow or an agent is contested, and the label changes which controls apply.

Anthropic’s line is architectural: whoever controls the code path. OpenAI’s governance white paper declines the binary entirely, saying there is “no clear line along which to draw a binary distinction”, and treats agenticness as a degree rather than a category. Noma Labs adds a competing vocabulary, distinguishing an “AI workflow” — “a predefined, static sequence of task execution where an LLM is embedded as an automated processing step” — from an “agentic workflow”, where “an AI agent dynamically decides which steps to take, which tools to invoke, and how to navigate toward a goal based on context”. Other researchers use “agentic workflow” for the whole family Anthropic calls agentic systems. The distinction is not academic for security: whether a pipeline counts as a workflow decides whether a team looks for the deterministic path or the autonomous one.

Questions and answers

What is the difference between an AI workflow and an AI agent?

In an AI workflow the developer fixes the code path in advance and the model is one step inside it. In an AI agent the model decides what to do next at each step. Anthropic: workflows are "systems where LLMs and tools are orchestrated through predefined code paths"; agents are "systems where LLMs dynamically direct their own processes and tool usage". A fixed pipeline that calls tools is therefore a workflow, not an agent, on Anthropic's reading.

Is a workflow more secure than an agent?

Not inherently. A workflow is deterministic, so the path is predictable, but it executes with the credentials its creator configured. The identity that triggers it can be decoupled from the identity that executes it, which Noma Labs identifies as the root cause of workflow identity hijacking: an unauthenticated request that runs privileged actions with the workflow's own service account. Determinism narrows what can go wrong; it does not narrow whose authority is used.

What are the common AI workflow patterns?

Anthropic names five that recur in production: prompt chaining (steps in a sequence, each LLM call processing the previous output), routing (classifying an input and sending it to the right specialist), parallelization (running independent subtasks, or the same task several times, in parallel), orchestrator-workers (a central LLM delegating subtasks and synthesizing results), and evaluator-optimizer (a generator looped against an evaluator). They are patterns, not a taxonomy, and can be combined.

Is every multi-step LLM pipeline a workflow?

On Anthropic's definition, yes: any system where LLMs and tools are orchestrated through predefined code paths. The line is contested. OpenAI says there is "no clear line along which to draw a binary distinction" and treats agenticness as a degree, and Noma Labs uses "agentic workflow" for the autonomous end of the family. Which label applies changes which controls a security team applies.

Sources

  1. Building effective agentsAnthropic, 19 Dec 2024
  2. A practical guide to building agentsOpenAI
  3. Practices for Governing Agentic AI SystemsOpenAI
  4. Workflow Identity Hijacking: The Silent Backdoor in AI WorkflowsNoma Labs, 9 Sep 2026